CVE-2023-21839 is an easily exploitable vulnerability in Oracle WebLogic Server (versions 12.2.1.3.0, 12.2.1.4.0, and 14.1.1.0.0) affecting its Core component. With a CVSS score of 7.5 (High), unauthenticated attackers can gain unauthorized access to critical or all accessible data via network access using T3 or IIOP protocols, with no user interaction required. This vulnerability is actively exploited in the wild, as confirmed by CISA, and has a Metasploit module available for remote command execution. It has garnered significant community discussion and media coverage, indicating widespread awareness and concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.2.1.3.0CPE matchmatch criteria | cpe:2.3:a:oracle:weblogic_server:12.2.1.3.0:*:*:*:*:*:*:* | ||
12.2.1.4.0CPE matchmatch criteria | cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:* | ||
14.1.1.0.0CPE matchmatch criteria | cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.